Description
docx4j is an open source Java library for creating, editing, and saving OpenXML packages, including DOCX, PPTX, and XLSX files. Prior to 11.5.14, PropertyResolver and adjacent helpers recursively follow the WordprocessingML w:basedOn style inheritance chain without cycle detection. A well-formed DOCX containing mutually based styles causes unbounded recursion in PropertyResolver.fillPPrStack and related effective-style resolution paths, resulting in StackOverflowError. Server-side conversion and table-of-contents processing of an untrusted document can terminate a worker thread, degrade a thread pool, or deny service, although isolation in disposable workers or safe containment of StackOverflowError can reduce the practical effect. The fix adds cyclic-style tracking and CyclicStylesException handling. This issue is fixed in version 11.5.14.
Published: 2026-09-14
Score: 7.5 High
EPSS: < 1% Very Low
KEV: No
Impact: Denial of Service
Action: Patch Immediately
AI Analysis

Impact

docx4j is an open-source Java library that processes OpenXML packages such as DOCX, PPTX, and XLSX files. Before version 11.5.14, the library's PropertyResolver and related helpers follow the WordprocessingML w:basedOn style inheritance chain without cycle detection. A DOCX containing mutually based styles causes the resolver to recurse indefinitely, leading to a StackOverflowError. When an untrusted document is processed—for example, during server-side conversion or table-of-contents generation—and this error occurs, a worker thread may terminate, degrade a thread pool, or cause a denial of service. The patch in 11.5.14 adds cycle tracking and exception handling to prevent the overflow.

Affected Systems

Applications that incorporate the docx4j library are vulnerable. The affected products are org.docx4j:docx4j-core and the Plutext distribution plutext:docx4j. Any deployment using a version older than 11.5.14 is subject to this flaw; versions 11.5.14 and later include cycle detection and exception handling that prevent the overflow.

Risk and Exploitability

The CVSS base score of 7.5 marks this as a high-impact denial of service vulnerability. An EPSS score of < 1% is now available, indicating a very low exploitation probability. The vulnerability is not listed in CISA's KEV catalog. Attackers need only supply a crafted DOCX file to an application that processes documents with docx4j, a common scenario in server-side conversion or document generation. If not mitigated, a single malicious file can consume stack space in a worker thread and potentially bring down a web service or batch job.

Generated by OpenCVE AI on September 20, 2026 at 23:44 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade the docx4j library to version 11.5.14 or later for both the core and Plutext distributions
  • If an upgrade cannot be performed immediately, inspect or sanitize incoming DOCX files for cyclic w:basedOn style chains before handing them to docx4j, or switch to a validated document parser that detects such cycles
  • Isolate document conversion into discrete, disposable worker processes or protected thread pools with strict resource limits and restart policies to contain any stack-overflow crashes
  • Monitor application logs for StackOverflowError occurrences and configure alerting to notify administrators of potential denial-of-service events

Generated by OpenCVE AI on September 20, 2026 at 23:44 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Github GHSA Github GHSA GHSA-gc95-3vw8-vg43 docx4j: Stack Overflow via Cyclic `w:basedOn` Style Chain leads to Denial of Service
History

Thu, 17 Sep 2026 20:30:00 +0000

Type Values Removed Values Added
First Time appeared Plutext
Plutext docx4j
Vendors & Products Plutext
Plutext docx4j

Wed, 16 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 14 Sep 2026 21:00:00 +0000

Type Values Removed Values Added
Description docx4j is an open source Java library for creating, editing, and saving OpenXML packages, including DOCX, PPTX, and XLSX files. Prior to 11.5.14, PropertyResolver and adjacent helpers recursively follow the WordprocessingML w:basedOn style inheritance chain without cycle detection. A well-formed DOCX containing mutually based styles causes unbounded recursion in PropertyResolver.fillPPrStack and related effective-style resolution paths, resulting in StackOverflowError. Server-side conversion and table-of-contents processing of an untrusted document can terminate a worker thread, degrade a thread pool, or deny service, although isolation in disposable workers or safe containment of StackOverflowError can reduce the practical effect. The fix adds cyclic-style tracking and CyclicStylesException handling. This issue is fixed in version 11.5.14.
Title docx4j: Stack Overflow via Cyclic `w:basedOn` Style Chain leads to Denial of Service
Weaknesses CWE-674
CWE-770
References
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'}


cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-09-16T15:54:21.969Z

Reserved: 2026-06-10T17:48:40.546Z

Link: CVE-2026-53752

cve-icon Vulnrichment

Updated: 2026-09-16T15:54:16.246Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-14T18:17:51.773

Modified: 2026-09-30T17:43:24.057

Link: CVE-2026-53752

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-20T23:45:06Z

Weaknesses
  • CWE-674

    Uncontrolled Recursion

  • CWE-770

    Allocation of Resources Without Limits or Throttling